Effective 13 September 2026
Privacy Policy
This Policy explains how personal data is collected, used, shared, retained, and protected when you use Zeelark websites, web applications, accounts, cards, payments, crypto, investment, security, and support services.
1. Who controls your data
The controller is the legal entity identified as the operator of Zeelark in your account or service disclosures. In this Policy, "we", "us", and "our" refer to that operator and its relevant affiliates. You can contact the privacy team through the Help and support area in Zeelark. Service-specific disclosures may identify an additional controller, joint controller, regulated provider, card issuer, payment provider, custodian, or verification provider.
2. Scope
This Policy applies to personal data processed through Zeelark and related support channels. A partner's privacy notice can also apply where that partner provides a regulated, payment, card, banking, crypto, verification, or custody service. Their notice controls their independent processing.
3. Data we collect
- Identity and profile data: legal name, email, telephone number, residential address, country, profile image, account identifiers, and verification status.
- Verification data: government identification images, proof of address or bank statements, selfies, selfie video, review notes, and information needed for customer due diligence.
- Authentication and security data: protected password and PIN records, one-time-code records, trusted-session identifiers, device and browser details, IP address, sign-in activity, failed attempts, security restrictions, and recovery records.
- Financial and transaction data: supported account balances, currencies, ledger entries, payment tags, recipients, transfer instructions, transaction references, exchange rates, fees, status, and card activity.
- Card data: card identifiers, masked card details, status, controls, limits, funding activity, and information needed by a card issuer or processor. Do not send a full card number or PIN to support.
- Crypto data: portfolio application and acknowledgements, holdings, supported asset and network activity, wallet addresses, transaction hashes, deposits, withdrawals, quotes, fees, watchlists, and review records.
- Investment data: strategy or trader selections, position amounts and duration, acknowledgements, status, modelled performance, fees, settlement entries, and reviews.
- Support data: ticket subjects and messages, up to two uploaded screenshots per ticket, live-chat messages, recovery-case messages and attachments, replies, status, and support-agent actions.
- Usage and technical data: app version, routes viewed, feature events, operating system, browser, installation state, error and service logs, and consent choices.
We do not ask you to put passwords, full PINs, one-time codes, private keys, or seed phrases in support messages.
4. Where data comes from
We receive data from you, your device, transactions performed through the service, counterparties, payment or card networks, banks, blockchain networks, market-data providers, identity-verification providers, Google sign-in where selected, support providers, fraud-prevention sources, and public or official sources where law permits.
5. Why we use data and our legal bases
- Contract: create and administer your account; authenticate you; process instructions; provide cards, payments, exchange, crypto, investment and support features; calculate fees; and communicate service status.
- Legal obligation: verify identity, keep records, respond to lawful requests, apply sanctions and financial-crime controls, report where required, and meet tax, accounting, consumer-protection, and regulatory duties.
- Legitimate interests: secure the service, prevent abuse and fraud, investigate incidents, improve reliability, protect customers and the operator, administer support, and understand aggregate product performance. We balance these interests against your rights.
- Consent: collect optional usage analytics and perform another optional activity where the app asks for consent. You can withdraw consent without affecting earlier lawful processing.
- Legal claims and public interest: establish or defend claims and support substantial public-interest processing where applicable law allows it.
If required information is not provided, we may be unable to open an account, verify identity, process an instruction, or provide a feature.
6. Who receives data
We disclose the minimum data reasonably needed to:
- affiliates and authorized staff who operate, secure, review, and support the service;
- hosting, storage, security, monitoring, email, identity-verification, payment, banking, card, market-data, blockchain infrastructure, custody, and professional-service providers;
- transaction counterparties and their providers where needed to complete an instruction;
- Google Analytics, only after analytics consent, using sanitized routes, approved feature events, and an opaque internal user ID rather than a name or email;
- Chatway for visitor activity and live chat, including the customer's name and email supplied to the messenger, chat content, visited URL, and technical information processed by its widget;
- Telegram for operational delivery of support tickets, ticket screenshots, and admin alerts to a restricted administrator channel;
- regulators, courts, law enforcement, tax authorities, or other parties where law requires or permits disclosure; and
- a buyer, investor, adviser, or successor during a proposed or completed corporate transaction, subject to confidentiality and applicable law.
We do not sell personal data for money. If applicable law treats a particular analytics or advertising disclosure as a sale or sharing, we will provide the controls that law requires.
7. International transfers
Providers and recipients may process data outside your country. Where applicable law requires safeguards, we use an adequacy decision, approved contractual clauses, a recognized certification, or another lawful transfer mechanism, together with supplementary protections where appropriate. Contact us to request information about the safeguards relevant to your data.
8. How long we keep data
We keep personal data only while needed for the purposes above and any legal, accounting, security, dispute, or regulatory period. Identity, customer-due-diligence, and transaction records may need to remain for several years after the relationship ends. Support records remain while a case is active and for a reasonable period afterward. Security logs are kept long enough to investigate abuse and protect accounts. Analytics data follows the configured Google Analytics retention period. Backups expire on a rolling schedule unless preservation is required.
The operator will publish or provide the confirmed category-by-category retention schedule or the criteria used to set each period.
9. Your privacy rights
Depending on your location and the legal basis, you may have rights to:
- receive information and access a copy of your personal data;
- correct inaccurate or incomplete data;
- request deletion or restriction;
- object to processing based on legitimate interests or direct marketing;
- receive portable data in an applicable structured format;
- withdraw consent at any time;
- request human review of a qualifying automated decision; and
- complain to the privacy regulator in your country.
Use the Help and support area in Zeelark to make a request. We may verify your identity and may retain data where law requires it or where it is needed for legal claims, fraud prevention, or another lawful exception. You can turn optional analytics on or off under Security and privacy. Routine email preferences do not stop essential security, verification, recovery, or support messages.
10. Cookies and local storage
Strictly necessary browser storage supports secure sessions, preferences, app-lock state, installation prompts, update delivery, and service continuity. Optional Google Analytics storage is used only after consent. Chatway may use storage for visitor activity, live chat, and chat session continuity. Browser or device controls can remove storage, but removing essential storage can sign you out or reset app preferences.
11. Security
We use access controls, protected authentication records, encrypted transport, session expiry, authorization checks, activity records, operational monitoring, restricted administration, and other proportionate safeguards. No system is completely secure. Keep your device and credentials protected, install updates, review trusted devices, and report suspected unauthorized access promptly.
12. Automated checks and human review
Automated rules can help detect failed authentication, unusual activity, service limits, sanctions concerns, fraud indicators, or transactions requiring review. These checks can delay or restrict an action. Where a solely automated decision has a legal or similarly significant effect and applicable law grants protection, you can ask for an explanation, provide additional information, and request human review through support.
13. Children
Zeelark is intended for adults who can enter a binding financial-services agreement. We do not knowingly offer ordinary customer accounts to children.
14. Changes, complaints, and contact
We may update this Policy when services, providers, or legal requirements change. We will change the effective date and provide additional notice where a material change requires it. Contact us through the Help and support area in Zeelark before complaining to a regulator so we can try to resolve the issue, although you may contact a regulator at any time.